mirror of
https://github.com/PerpetualSoftware/pad.git
synced 2026-09-11 21:39:01 +00:00
fb40a62e23
Set annotations.untrustedContentHint=true on WebMCP tool descriptors for every catalog tool whose output surfaces user-authored workspace content. Signals the browser agent to treat results as unverified input (prompt-injection hardening, DR-2). Derivation is a small pure helper (surfacesUntrustedContent) parallel to isAllReadOnly; the builder stays side-effect-free. The rule is derived from the action set, not the tool name: a tool surfaces content unless EVERY action is content-free server introspection (server-info / version / tool-surface). This correctly flags pad_meta — despite its name it exposes a `bootstrap` action that returns the workspace bootstrap blob (user + workspace content) — while still exempting a hypothetical pure version/meta surface. Add a consent manual-verification checklist (web/src/lib/webmcp/README.md) capturing the Chrome-149 origin-trial steps that can't run in CI: read tools run quiet, mutating tools prompt per-invocation consent, no workspace arg is offered, untrusted-content honesty. Refs TASK-1896 / PLAN-1888 Claude-Session: https://claude.ai/code/session_01KmxkPxLksjf1pmrZDpsnTJ
Pad Web UI
SvelteKit 2 + Svelte 5 frontend for Pad, compiled to static files and embedded into the Go binary.
Development
npm install
npm run dev # Dev server at localhost:5173 (proxies API to localhost:7777)
npm run build # Production build to build/
npm run check # Type checking with svelte-check
When developing, run the Go backend separately with make dev from the project root.
Building for Production
Do not build in isolation. Always use make build from the project root — this builds the web frontend, then compiles the Go binary with the build output embedded via //go:embed.
Stack
- Svelte 5 with runes (
$state,$derived,$effect) - SvelteKit 2 with
adapter-static(SPA mode) - Tiptap block editor with markdown round-trip
- svelte-dnd-action for drag-and-drop in board/list views
- SSE for real-time updates
- TypeScript throughout
Structure
src/
routes/ SvelteKit pages
+layout.svelte App shell (sidebar + main)
+page.svelte Landing/redirect
[workspace]/
+page.svelte Dashboard (collections, phases, activity)
+layout.svelte SSE connection per workspace
[collection]/
+page.svelte Collection view (board/list)
[collection]/[item]/
+page.svelte Item detail + editor
conventions/ Purpose-built conventions page
playbooks/ Purpose-built playbooks page
settings/ Workspace settings
lib/
api/client.ts HTTP API client
components/
layout/ Sidebar, navigation
editor/ Tiptap editor, raw markdown editor
fields/ FieldEditor, relation picker
items/ ItemCard, ItemDetail
collections/ BoardView, ListView
common/ StatusBadge, badges, modals
search/ CommandPalette
activity/ ActivityFeed
stores/ Svelte 5 reactive stores
workspace.svelte.ts Workspace state
collections.svelte.ts Collection + item state
ui.svelte.ts Sidebar, mobile state
types/index.ts TypeScript types and constants
app.css Global styles and design tokens